Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2015-9169 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400… Msm8909w Firmware Mitigation only Fix from $1,9502018-04-18 HIGH 7.5 CVE-2015-9119 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MD… Mdm9206 Firmware Mitigation only Fix from $1,9502018-04-18 HIGH 7.5 CVE-2015-9123 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, IPQ4019, MDM… Mdm9206 Firmware Mitigation only Fix from $1,9502018-04-18 HIGH 7.5 CVE-2014-10062 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, MS… Mdm9206 Firmware Mitigation only Fix from $1,9502018-04-18 HIGH 7.5 CVE-2014-10047 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, when writing the Full Disk Encryption k… Sd 400 Firmware Mitigation only Fix from $1,9502018-04-18 HIGH 7.5 CVE-2014-10055 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, there could be leakage of protected con… Sd 400 Firmware Mitigation only Fix from $1,9502018-04-18 HIGH 7.5 CVE-2018-10189 An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking th… Mautic 2.13.0+ Fix from $1,9502018-04-17 HIGH 8.8 CVE-2018-5430 KEVEPSS 50% The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server fo… Jasperreports Server after 6.4.2 Fix from $1,9502018-04-17 MEDIUM 5.3 CVE-2018-10178 The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisited… Fromdoctopdf 13.611.13.2303+ Fix from $1,6002018-04-17 CRITICAL 9.8 CVE-2018-10106 D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdo… Dir 815 Firmware after 2.07.b01 Fix from $2,3002018-04-16 MEDIUM 5.3 CVE-2018-1000169 An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler… Jenkins after 2.107.1 Fix from $1,6002018-04-16 MEDIUM 5.3 CVE-2014-1686 MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation. Mediawiki No fix yet Fix from $1,6002018-04-16 HIGH 7.8 CVE-2017-0361 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext. Debian Linux 1.27.2 / 1.28.1+ Fix from $1,9502018-04-13 MEDIUM 5.3 CVE-2018-10082 CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact… Cms Made Simple after 2.2.7 Fix from $1,6002018-04-13 CRITICAL 9.8 CVE-2015-0152 D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the ad… Dir 815 Firmware 2.07.b01+ Fix from $2,3002018-04-12 HIGH 7.5 CVE-2018-1086 pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove th… Debian Linux Mitigation only Fix from $1,9502018-04-12 HIGH 7.5 CVE-2014-6309 The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 a… Kaazing Websocket Gateway Mitigation only Fix from $1,9502018-04-12 HIGH 7.5 CVE-2017-6910 The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 … Kaazing Gateway 4.4.2 / 4.5.3+ Fix from $1,9502018-04-12 MEDIUM 5.3 CVE-2018-9842EPSS 16% CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message. Password Vault 9.7+ Fix from $1,6002018-04-12 MEDIUM 5.9 CVE-2018-0018 On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to bypass firewall rules, leading… Junos Patch available Fix from $1,6002018-04-11 MEDIUM 5.3 CVE-2018-10028 joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI. Joyplus Cms Mitigation only Fix from $1,6002018-04-11 MEDIUM 5.7 CVE-2018-7930 The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C567) has an information leak vu… Mate 9 Firmware Mitigation only Fix from $1,6002018-04-11 HIGH 7.5 CVE-2017-18072 In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6… Mdm9206 Firmware Mitigation only Fix from $1,9502018-04-11 MEDIUM 5.3 CVE-2015-1957 IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-mid… Websphere Mq 7.5.0.6 / 8.0.0.3+ Fix from $1,6002018-04-10 MEDIUM 5.3 CVE-2014-2078 The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses … Open Xchange Appsuite Mitigation only Fix from $1,6002018-04-10 HIGH 7.5 CVE-2015-0172 IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unsp… Security Siteprotector System No fix yet Fix from $1,9502018-04-10 MEDIUM 5.3 CVE-2018-9922 An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weix… Icms after 7.0.7 Fix from $1,6002018-04-10 CRITICAL 9.8 CVE-2018-9852 In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embedding a FROM clause in a… Gxlcms Qy No fix yet Fix from $2,3002018-04-08 HIGH 7.5 CVE-2018-9325 Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names. Etherpad 1.6.4+ Fix from $1,9502018-04-07 MEDIUM 5.9 CVE-2014-2359 OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or spoof devices by reading clear… Ft1 Firmware Mitigation only Fix from $1,6002018-04-06